Back to skill

Security audit

Templated

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for managing Templated through OOMOL, but its fallback setup uses unverified remote installer scripts that execute directly in a shell.

Review the setup path before installing. Prefer installing the oo CLI from a pinned, verifiable release or inspect the installer before running it, and require explicit approval before create_render or delete_render actions against your Templated account.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:61
Finding

Unverified Remote Installer Scripts Executed Directly by Shells

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 61–65
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

bash
curl -fsSL https://cli.oomol.com/install.sh | bash    # macOS / Linux
powershell
irm https://cli.oomol.com/install.ps1 | iex           # Windows PowerShell

Technical Analysis

The first-time setup instructions download mutable scripts from an external server and immediately execute their contents using Bash or PowerShell. Neither command pins a specific release, verifies a cryptographic signature or checksum, nor gives the user an opportunity to inspect the downloaded script before execution.

HTTPS protects the connection in transit but does not guarantee that the remote server, hosting account, installation script, or upstream release process has not been compromised. Because the retrieved payload can change after the Skill has been reviewed, its effective behavior cannot be determined from the audited package alone.

Installing the oo CLI supports the Skill's declared purpose, but piping an unverified remote response directly into a shell exceeds the minimum mechanism necessary to perform that installation. A pinned, independently verified artifact would provide the same functionality with a smaller supply-chain risk.

Attack Path

  1. The oo command is absent, causing an oo: command not found error.
  2. The Agent or user follows the first-time setup instructions in SKILL.md.
  3. An attacker compromises the OOMOL distribution server, DNS or hosting infrastructure, installation-script publishing process, or another relevant supply-chain component.
  4. The attacker replaces the remotely served installer with a malicious script.
  5. curl | bash or irm | iex passes that script directly to a command interpreter without integrity verification.
  6. The malicious payload executes with all permissions available to the user or process that invok ...[truncated 736 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove both direct pipe-to-shell installation commands.
  2. Pin installation instructions to a specific, immutable CLI release and official artifact URL.
  3. Download the artifact to a local file without executing it immediately.
  4. Publish and require verification of a SHA-256 checksum or, preferably, a cryptographic signature whose trusted public key is distributed through a separate channel.
  5. Abort installation if verification fails.
  6. Allow the downloaded script or package to be inspected before execution.
  7. Prefer a trusted operating-system package manager with explicit version pinning and package-signature verification.
  8. Instruct users not to run the installer as an administrator or with sudo unless a documented installation step strictly requires elevation.
  9. Document the files, directories, and permissions modified by installation so users can evaluate the required privilege scope.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill instructs the agent to install software by piping a remote script directly into the shell (curl ... | bash). This creates a supply-chain and remote code execution risk: if the remote host, network path, or script is compromised, arbitrary code will execute on the user's machine with the agent's privileges.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description says to use this skill for "ANY Templated request" and "Whenever a task involves Templated," which is a very broad activation rule for a manifest/markdown file. It does not provide narrower trigger constraints or negative examples, so ordinary mentions of Templated could unintentionally invoke the skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.